extensis kayıtları
extensis üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-787 Out-of-bounds Write2
- CWE-20 Improper Input Validation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2013-3944İstismar yok | Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via extensis · mrsid · CWE-787 | Yüksek7,8 | — | %27,5 | 2 Oca 2020 |
36İzleyin | CVE-2022-24254İstismar yok | An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execextensis · portfolio · CWE-434 | Yüksek8,8 | — | %2,6 | 1 Mar 2022 |
36İzleyin | CVE-2022-24252İstismar yok | An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to executeextensis · portfolio · CWE-434 | Yüksek8,8 | — | %2,3 | 1 Mar 2022 |
35İzleyin | CVE-2022-24255İstismar yok | Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.extensis · portfolio · CWE-798 | Yüksek8,8 | — | %1,4 | 1 Mar 2022 |
35İzleyin | CVE-2022-24251İstismar yok | Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload functextensis · portfolio · CWE-434 | Yüksek8,8 | — | %1,3 | 1 Mar 2022 |
35İzleyin | CVE-2022-24253İstismar yok | Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransfeextensis · portfolio · CWE-434 | Yüksek8,8 | — | %1,3 | 1 Mar 2022 |
32İzleyin | CVE-2013-3946İstismar yok | Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via aextensis · mrsid · CWE-787 | Yüksek7,8 | — | %2,5 | 2 Oca 2020 |
32İzleyin | CVE-2013-3945İstismar yok | The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.extensis · mrsid · CWE-20 | Yüksek7,8 | — | %2,1 | 2 Oca 2020 |
24İzleyin | CVE-2017-18006İstismar yok | netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447.extensis · portfolio netpublish · CWE-79 | Orta6,1 | — | %0,7 | 31 Ara 2017 |
21İzleyin | CVE-2005-4510Kavram kanıtı | Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences inextensis · netpublish server | Orta5,0 | — | %2,9 | 22 Ara 2005 |
- CVE-2013-394439İzleyin
Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via
YüksekCVSS 7,8İstismar yokEPSS %28extensis · mrsid2 Oca 2020
- CVE-2022-2425436İzleyin
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to exec
YüksekCVSS 8,8İstismar yokEPSS %3extensis · portfolio1 Mar 2022
- CVE-2022-2425236İzleyin
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute
YüksekCVSS 8,8İstismar yokEPSS %2extensis · portfolio1 Mar 2022
- CVE-2022-2425535İzleyin
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.
YüksekCVSS 8,8İstismar yokEPSS %1extensis · portfolio1 Mar 2022
- CVE-2022-2425135İzleyin
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload funct
YüksekCVSS 8,8İstismar yokEPSS %1extensis · portfolio1 Mar 2022
- CVE-2022-2425335İzleyin
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransfe
YüksekCVSS 8,8İstismar yokEPSS %1extensis · portfolio1 Mar 2022
- CVE-2013-394632İzleyin
Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a
YüksekCVSS 7,8İstismar yokEPSS %2extensis · mrsid2 Oca 2020
- CVE-2013-394532İzleyin
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.
YüksekCVSS 7,8İstismar yokEPSS %2extensis · mrsid2 Oca 2020
- CVE-2017-1800624İzleyin
netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447.
OrtaCVSS 6,1İstismar yokEPSS %1extensis · portfolio netpublish31 Ara 2017
- CVE-2005-451021İzleyin
Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in
OrtaCVSS 5,0Kavram kanıtıEPSS %3extensis · netpublish server22 Ara 2005